This article used to be a guide to choosing a third party assessment organisation. It is now largely a guide to why you do not need one yet.
The current position. Under the class deviation signed September 3, 2026, mandatory third party assessment is suspended through November 2028. Levels 1 and 2 are satisfied by self assessment. Contracting officers have been told to strip the requirement out of contracts.
If you were mid conversation with a C3PAO, that conversation can pause. If you were budgeting for an assessment this year, that budget is free.
Two exceptions worth checking. A prime can impose stricter requirements than the regulation through your subcontract, and some will. And nothing prevents you seeking a voluntary assessment if a customer relationship genuinely depends on it. Neither is common.
What to do with the money instead
The assessment was never the thing that made you secure. It was the thing that proved it. With the proof requirement paused, the sensible move is to spend the same budget on the underlying gaps, which is the part that carries actual risk.
Concretely: get an accurate SPRS score, close the five point controls, write a system security plan that matches reality, and put in place the evidence trail you would have needed for an assessment anyway.
You will need all of it in 2028, and you will need it much sooner than that if the Defense Contract Management Agency assesses you or a prime asks hard questions.
Why the assessor market matters anyway
There is a practical reason not to wait until 2028. Before the suspension, over 160 candidate assessment organisations were queued for authorisation at roughly one a week. That backlog did not disappear. When the requirement returns, the queue returns with it, and firms that left everything until then will be competing for scarce capacity against a deadline.
The firms that come out of this well will be the ones that used a quiet two years.
